Skip to content

Filescan module reports files that don't exist #32

@furrnace

Description

@furrnace

on one machine the Filescan module reported 3 files that do not exist when I look for them as root:

/usr/bin/tor, YARA rule SUSP_ELF_Tor_Client / Detects VPNFilter malware

/opt/base/sbin/cinit, YARA rule SUSP_ELF_LNX_UPX_Compressed_File / Detects a suspicious ELF binary with UPX compression
there is no directory /opt/base !

/opt/base/sbin/nginx, YARA rule SUSP_ELF_LNX_UPX_Compressed_File / Detects a suspicious ELF binary with UPX compression
there is /usr/sbin/nginx but it is not compressed with UPX

What could be the reason for such a result? Is this a bug?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions